peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,436 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

317,855 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2019-0752 KEV EXP A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… Patch first 7.5 high 81.6% 2019-04-09
CVE-2023-4911 KEV EXP A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue coul… Patch first 7.8 high 81.4% 2023-10-03
CVE-2010-2883 KEV EXP Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote at… Patch first 7.3 high 81.4% 2010-09-09
CVE-2019-9621 KEV EXP Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SS… Patch first 7.5 high 81% 2019-04-30
CVE-2016-7255 KEV EXP The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Patch first 7.8 high 81% 2016-11-10
CVE-2017-0037 KEV EXP Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSp… Patch first 8.1 high 80.4% 2017-02-26
CVE-2012-4969 KEV EXP Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execu… Patch first 8.1 high 80.3% 2012-09-18
CVE-2016-7201 KEV EXP The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corrup… Patch first 8.8 high 80% 2016-11-10
CVE-2010-0738 KEV EXP The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 bef… Patch first 5.3 medium 79.4% 2010-04-28
CVE-2021-21551 KEV EXP Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or inf… Patch first 8.8 high 79.2% 2021-05-04
CVE-2013-0074 KEV EXP Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows re… Patch first 7.8 high 78.9% 2013-03-13
CVE-2012-4792 KEV EXP Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that… Patch first 8.8 high 78.8% 2012-12-30
CVE-2020-6418 KEV EXP Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch first 8.8 high 78.8% 2020-02-27
CVE-2021-22555 KEV EXP A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or… Patch first 8.3 high 78.7% 2021-07-07
CVE-2020-8816 KEV EXP Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. Patch first 7.2 high 78.2% 2020-05-29
CVE-2013-1347 KEV EXP Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an obje… Patch first 8.8 high 77.7% 2013-05-05
CVE-2014-6352 KEV EXP Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows R… Patch first 7.8 high 77.5% 2014-10-22
CVE-2014-1761 KEV EXP Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automati… Patch first 7.8 high 77.5% 2014-03-25
CVE-2013-3897 KEV EXP Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute… Patch first 8.8 high 77.3% 2013-10-09
CVE-2019-1429 KEV EXP A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engin… Patch first 7.5 high 77.3% 2019-11-12
CVE-2020-10221 KEV EXP lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the… Patch first 8.8 high 77.1% 2020-03-08
CVE-2019-15949 KEV EXP Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin u… Patch first 8.8 high 77% 2019-09-05
CVE-2018-15133 KEV EXP In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially un… Patch first 8.1 high 76.8% 2018-08-09
CVE-2016-3718 KEV EXP The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (S… Patch first 5.5 medium 76.7% 2016-05-05
CVE-2008-0015 KEV EXP Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX… Patch first 8.8 high 76.7% 2009-07-07
CVE-2018-15811 KEV EXP DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. Patch first 7.5 high 76.1% 2019-07-03
CVE-2015-0016 KEV EXP Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP… Patch first 7.8 high 75.8% 2015-01-13
CVE-2016-3715 KEV EXP The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. Patch first 5.5 medium 75.3% 2016-05-05
CVE-2018-8298 KEV EXP A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory C… Patch first 7.5 high 74.5% 2018-07-11
CVE-2019-1458 KEV EXP An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation… Patch first 7.8 high 74.3% 2019-12-10
← previous page 5 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt